Path traversal in Ansible Lightspeed MCP server via prompt injection
A path traversal vulnerability in Ansible Lightspeed's Model Context Protocol server allows attackers to manipulate AI agents through indirect prompt injection, enabling unauthorized file writes and potential system compromise.
Disclosed 22 July 2026 · Record updated 13 September 2026
Impact
Attackers can write files to unauthorized locations, expose sensitive host information, and execute malicious commands leading to full system compromise.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44192
